aws-assume-role-lib
Assumed role session chaining (with credential refreshing) for boto3
Decision gist · record as of 2026-08-14
Yes, if you are already using boto3 and need to assume roles programmatically. The library genuinely simplifies a common pattern and has no known vulnerabilities. However, be aware that the package is abandoned—last updated in May 2022 with no recent commits. If you need active maintenance or compatibility updates for future boto3 versions, consider whether you can afford to fork it or maintain it internally, or evaluate whether AWS's built-in profile-based role assumption in ~/.aws/config meets your needs instead.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires boto3 to be installed and valid AWS credentials configured for the initial session.
- Low install friction with a single runtime dependency on boto3.
- However, the package is abandoned—last commit was 2022-11-02 and no releases since 2022-05-14.
License · maintenance · safety
Apache-2.0 (permissive) — Licensed under Apache-2.0 (permissive). You may use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.
last release 2022-05-14 (1553 days) · last repo commit 2022-11-02 · 162 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 622,935 downloads/mo, #5,706 on PyPI
Alternatives
Verify before relying
import boto3
from aws_assume_role_lib import assume_role
session = boto3.Session()
assumed_role_session = assume_role(session, "arn:aws:iam::123456789012:role/MyRole")
print(assumed_role_session.client("sts").get_caller_identity())- Whether the package works correctly with recent boto3 versions released after 2022-05-14.
- Whether credential refresh behavior remains compatible with current AWS STS API behavior.
What it is and what it does
aws-assume-role-lib wraps the verbose boilerplate of AWS STS AssumeRole into a single function call on a boto3 Session. Instead of manually calling sts.assume_role(), parsing the response, and creating a new session with temporary credentials, you pass a session and role ARN to assume_role() and get back a session ready to use. The library automatically generates a role session name if you don't provide one, and crucially, it handles credential expiration by refreshing them transparently when needed—eliminating the need to call AssumeRole on every Lambda invocation or manually track credential lifetime.
The package depends only on boto3 and is designed to work across Python 3.6 through 3.10. It supports all standard AssumeRole parameters (policies, duration, external ID, tags, etc.) and lets you pass Policy as a dict instead of a JSON string, and DurationSeconds as a timedelta. For Lambda workloads, you initialize the assumed role session once outside the handler and reuse it across invocations, calling AssumeRole only when credentials actually expire.
Use it for
- Assume an AWS role in a Lambda function once at initialization and reuse it across invocations without re-assuming on every call.
- Simplify multi-account AWS workflows by chaining role assumptions with automatic credential refresh in application code.
- Reduce boilerplate when writing boto3 scripts that need to operate under an assumed role with temporary credentials.
- Implement cross-account access patterns in microservices where each service assumes a role in another account on startup.
- Build automation tools that assume different roles for different tasks without manually managing STS calls and session creation.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you are already using boto3 and need to assume roles programmatically.
The library genuinely simplifies a common pattern and has no known vulnerabilities. However, be aware that the package is abandoned—last updated in May 2022 with no recent commits. If you need active maintenance or compatibility updates for future boto3 versions, consider whether you can afford to fork it or maintain it internally, or evaluate whether AWS's built-in profile-based role assumption in ~/.aws/config meets your needs instead.
Install
aws-assume-role-lib on PyPI
Before you install
Low install friction with a single runtime dependency on boto3. However, the package is abandoned—last commit was 2022-11-02 and no releases since 2022-05-14. It remains marked Production/Stable and has no known vulnerabilities, but you will not receive updates or maintenance.
Requires boto3 to be installed and valid AWS credentials configured for the initial session.
License in practice
Licensed under Apache-2.0 (permissive). You may use, modify, and distribute this package freely in commercial and private projects with minimal restrictions.
Quickstart
import boto3
from aws_assume_role_lib import assume_role
session = boto3.Session()
assumed_role_session = assume_role(session, "arn:aws:iam::123456789012:role/MyRole")
print(assumed_role_session.client("sts").get_caller_identity())
Verify before relying
- Whether the package works correctly with recent boto3 versions released after 2022-05-14.
- Whether credential refresh behavior remains compatible with current AWS STS API behavior.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.6,<4.0 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | 1 packageboto3 |
| Maintenance | Abandoned 1,553 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 622,935 / month, #5,706 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersIntended Audience :: System AdministratorsLicense :: OSI Approved :: Apache Software LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.6Programming Language :: Python :: 3.7Programming Language :: Python :: 3.8Programming Language :: Python :: 3.9Topic :: Software Development :: LibrariesTopic :: Utilities |
Evidence: aws_assume_role_lib-2.10.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “boto3 assume role”
- aws-assume-role-libSimplifies AWS role assumption in boto3 by wrapping STS AssumeRole…
- boto3-assumeWraps boto3 to create AWS IAM assume-role sessions with automatic…
- gimme-aws-credsA CLI tool that obtains temporary AWS credentials by authenticating…
Give your agent the search over MCP, or paste the wish link into any chat.
More Libraries packages
urllib3 is an HTTP client library that provides thread-safe connection pooling, SSL/TLS verification, multipart file uploads, request retries, compression support, and proxy handling for Python applications.
Requests is a Python HTTP library that simplifies sending HTTP/1.1 requests with automatic handling of headers, authentication, cookies, and response parsing.
Pluggy provides a plugin system that lets you define hook specifications and register implementations to be called in sequence, enabling extensible Python applications without tight coupling.
Install it if you're building an extensible application or framework.
Provides parsing, arithmetic, and recurrence rule computation for dates and times, with timezone support and iCalendar RFC compliance.
Install it if you need to parse flexible date strings, compute relative dates, handle timezones, or work with recurrence rules—it's the de facto choice for these tasks.
Six provides utility functions to write Python code that runs on both Python 2.7 and Python 3.3+, smoothing over language differences between the two versions.
pytest is a testing framework that lets you write test functions using plain assert statements and automatically discovers and runs them, with detailed failure reporting.
See also boto_session_manager · boto3-assume · gimme-aws-creds · aws-sso-lib · placebo · arn · requests-aws-sign · aws-msk-iam-sasl-signer-python · aws-cdk.aws-iam · eks-token